Jobs · Information Technology · Texas

Field CISO

CyberJobs.Com · Dallas, TX · 2 days ago
Information TechnologyFull-time

About the role

Join a purpose-driven winning team, committed to results, in an inclusive and high-performing culture. Global Banking and Markets (GBM) is a leading Canadian Capital Markets and Investment Banking business with a growing platform in the US and Latin America, operating globally for over 100 years.

The US Deputy Chief Information Security Officer (Deputy CISO) will support the MD & US CISO in building robust United States technology risk related controls and processes and ensure they are maintained and adhered to in the assigned portfolio.

Responsibilities

  • Champion a customer-focused culture to deepen relationships with Sr. leadership, peers, and functional groups by leveraging IT and risk expertise.
  • Partner across senior executives US CIO, Global CISO, Risk, Operations, compliance and legal teams to deliver improved US regulatory outcomes and strategies.
  • Support the US 1st line Technology Risk, Cyber Security and Internal Controls teams.
  • Collaborate with the MD & CISO, US CIO, and Global CISO in leading frequent interaction and reporting to US Federal Regulators.
  • Oversee critical 1st Line of Defense (1B) function in highly regulated US Technology realm with ongoing guidance to support the implementation of, and compliance to, established IT Standard, Policies, Procedures, regulatory, operational risk and cyber risk requirements.
  • Support in leading US 1st Line of Defense (1A) teams and Risk owners, to build their capability to identify, assess, mitigate and monitor risks associated with their use of information and IT systems.
  • Support in managing Technology Risk identification, assessment, prioritization for relevant business areas.
  • Ensure observations, issues and outputs are tracked and actioned.
  • Support in leading US Technology risk control testing and monitoring and guides all US-based Technology Risk Owners with remediation plans.
  • Partner with and face other risk groups to assess, implement and communicate new/updated risk controls, frameworks, policies, risk indicators, metrics and limits.
  • Oversee analyses of systems or asset data and deliver monthly/quarterly reporting for senior management, Internal Controls, GRM, Compliance, Audit, Operational Risk or 1A stakeholders.
  • Lead team that develops reports and presentations to deliver updates on KPIs/KRIs to various audiences, including senior business risk committees.
  • Develop or manage programs to establish KRI performance within the bank’s risk tolerance.
  • Prioritize risk activities, ensure timely remediation and escalate when necessary.
  • Evangelize for Technology Risk and promote a strong risk culture in partnership with the risk owners.
  • Co-ordinate SOX control testing and facilitate evidence collection and escalate conflicts or roadblocks to relevant SME to ensure control testing is completed as per schedule.
  • Prepare quarterly SOX attestations.
  • Ensure sound and consistent information security architectures are leveraged and effectively communicated to local business lines and technology support groups.
  • Support in directing, assuring, and advancing the security of the Scotiabank Group's networks, including the reliability and manageability of logical access security and application change control operations locally.
  • Pursue security and control process improvements and the protection of emerging technologies and new delivery systems in collaboration with the Central ESS/CSS/GSS functions.

Requirements

  • Candidates should have a breadth of Technology and non-financial Risk management experience (10+ years in governance, operations, audit, cyber, control functions, compliance, risk management).
  • Expert leadership, communication (both verbal and written) and influencing capability, supported by well-developed logical thinking competencies.
  • Proficient written and verbal communication required at all levels of the organization.
  • Expert Technology risk management experience in multiple areas including internal controls, systems design, security, availability/stability/resiliency, disaster recovery, third-party risk management, change management, release management, audit, regulatory risk, logical access, software currency.
  • Exposure to cloud controls would be an asset.
  • Proven experience in risk or Cyber security leadership preferably with deep knowledge of US and GBM businesses including related systems, procedures, regulations expected.
  • Ability to balance contesting or conflicting goals of various departments and stakeholders which requires a mature, diplomatic approach and advanced negotiation, project management, governance and influencing skills.
  • Strong presentation design and delivery expected as part of the leadership team.
  • Data Analytics and Visual dashboarding would be desirable.
  • Knowledge or understanding of Risk/Control frameworks (ITIL, ISO, COBIT, NIST, FFIEC).
  • Advanced degree in Computer Science, Engineering, Business Commerce or equivalent experience.
  • Additional relevant Certifications would be an asset - ITIL V3 Foundation Cert. in ITSM, COBIT, CRISC, CISSP.

Qualifications

Candidates must have a strong background in technology risk management and leadership, with a deep understanding of US and GBM businesses, including related systems, procedures, and regulations.

Skills

  • Expert leadership and communication skills.
  • Strong technical expertise in technology risk management, including internal controls, systems design, security, and cloud controls.
  • Ability to balance contesting or conflicting goals of various departments and stakeholders.
  • Advanced negotiation, project management, governance, and influencing skills.
  • Strong presentation design and delivery skills.
  • Data Analytics and Visual dashboarding skills (desirable).

Similar jobs

Field CISO

CyberJobs.ComCoppell, TX· 2 days ago
Information Technologyapply on cyberjobs.com

Field CISO

DrataSan Francisco Bay Area· 6 days ago
Information Technology$210k–$350k/yrapply on jobs.ashbyhq.com

Field CISO

JFrogSunnyvale, CA· 3 wk ago
RemoteInformation Technology$240k–$255k/yrapply on grnh.se

Field CISO

CyberJobs.ComAtlanta, GA· 2 days ago
Information Technologyapply on cyberjobs.com

Field CISO

AMDTUnited States· 2 wk ago
RemoteBusiness Developmentapply on t.gohiring.com

Field CISO

AMDTAlpharetta, GA· 2 wk ago
RemoteInformation Technologyapply on auvesy-mdt-holding-gmbh.jobs.personio.de